CiberLATAMbywhalemate

Chile tightens customer authentication for transfers

Chile’s CMF is enforcing stronger customer authentication for transfers and digital payments, as fraud and identity theft risks rise.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

Chile’s CMF has begun strictly enforcing its Customer Authentication standard for electronic transfers and digital payments. The move is aimed at digital fraud and identity theft, and reporting indicates that for most users it means phasing out the old plastic coordinate cards.

Chile’s CMF has begun strictly enforcing reinforced customer authentication rules for electronic transfers and digital payments, amid alerts over digital fraud and identity theft. For most users, that also means moving away from the traditional plastic coordinate cards.

What changes with ARC?

Reinforced Customer Authentication, according to El Mostrador’s coverage, is becoming the standard for validating digital transactions in Chile’s banking system. The change is intended to tighten access to transfers and payments at a time when identity verification has become a sensitive point in fraud attempts.

At the same time, public debate over these measures has been accompanied by new warnings about vishing in Chile. The reporting noted that banks should not ask over the phone for secret keys, transfer passwords, coordinate codes, or approval of transactions. When that happens, the recommendation is to immediately block the channels and file a formal complaint with the institution.

What channels must financial institutions keep open?

Financial institutions are required to maintain 24/7 blocking channels for cards, apps, and web access, according to the same coverage. That requirement is central to incident response, because users are not tied to banking hours when they need to stop unauthorized access or a suspicious transaction.

Scotiabank Chile, for its part, provides specific channels for reporting fraud and phishing, including an emergency phone line and a dedicated email address for phishing incidents. In its prevention materials, the bank also identifies attack types such as phishing, SIM swapping, and skimming within its online channels.

The framework is based on Law No. 20,009 and the reporting obligations before the CMF, which set out the institutional response to digital banking fraud in Chile. Within that structure, ARC serves as an additional verification layer, while complaint and 24/7 blocking channels are the immediate containment route once an incident has already occurred.

The coverage on vishing and Scotiabank’s alerts show how responsibilities are now divided among banks, the regulator, and users: do not hand over credentials by phone, cut off access as soon as an attempted scam is detected, and use the formal reporting channels each institution must keep active.

Sources

View all